An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.
History

Mon, 08 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in AnyDesk before 9.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients. An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CPEs cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Anydesk
Anydesk anydesk
Vendors & Products Anydesk
Anydesk anydesk

Thu, 06 Nov 2025 17:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in AnyDesk before 9.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-06T00:00:00.000Z

Updated: 2025-12-08T16:43:33.236Z

Reserved: 2025-03-10T00:00:00.000Z

Link: CVE-2025-27918

cve-icon Vulnrichment

Updated: 2025-11-12T16:11:08.828Z

cve-icon NVD

Status : Modified

Published: 2025-11-06T18:15:40.793

Modified: 2025-12-08T17:16:13.713

Link: CVE-2025-27918

cve-icon Redhat

No data.